Introduction

What?

Exploring the core processes within a Windows OS and understand what normal behaviour is.

Why?

This foundational knowledge will help identify malicious processes running on an endpoint.

How?

Windows core boot